Phishing collection point

  • Profile Image
    Barry Irwin
    Asked on November 15, 2011 at 03:04 AM

    Hi

     

    A phsihgin site against South african financial institutions is using a form on jotform, for the collection and email of details:

     

    The relevant snippit of code is shown below:

    <form class="jotform-form" action="http://www.jotform.com/submit.php" method="post" name="form_13125257129" id="13125257129" accept-charset="utf-8"> <input type="hidden" name="formID" value="13125257129" /> <div class="form-all">

    I can provide full HTML to you security team as needed
  • Profile Image
    idarktech
    Answered on November 15, 2011 at 03:09 AM

    Hi Barry,

    We have suspended both the account and the form. They are disguising it to show differently to us so they can bypass our anti-pishing scanner.  These type of forms are the hardest to detect for our phishing filter but thanks to you for reporting this form.

    Thank you for your cooperation and have a great day!